Linux 'io_uring' security blindspot allows stealthy rootkit attacks
ID: e7ec3d6f-bde8-5efb-a9bf-9af9222d599e
STIX ID: report--e7ec3d6f-bde8-5efb-a9bf-9af9222d599e
Feed Name: Bleeping Computer
ARMO researchers disclosed that the Linux io_uring interface creates a significant runtime-security blindspot and released a proof-of-concept rootkit called "Curing" which abuses io_uring to execute remote commands and evade syscall-based detection; testing showed well-known runtime-security tools (e.g., Falco and default Tetragon) failed to detect the activity, prompting recommendations to adopt Kernel Runtime Security Instrumentation (KRSI)/eBPF mitigations and noting that Google disabled io_uring by default on Android/ChromeOS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
